SQL Injection Vulnerability in MegaCMS by CRM Sistemas de Fidelizacion
CVE-2026-3325
10CRITICAL
What is CVE-2026-3325?
A SQL injection vulnerability exists in MegaCMS v12.0.0 that affects the "id_territorio" parameter of the "/web_comunications/cms/get_provincias" endpoint. This issue is caused by insufficient validation and sanitization of user input, allowing an unauthenticated attacker to manipulate the parameter through a POST request. If exploited, the attacker can execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information.
Affected Version(s)
MegaCMS 12.0.0
